Privacy Notice/Your Privacy Rights

Last Updated: 10.03.2022

This Privacy Notice applies to information that each of Michael Kors (Germany) GmbH, Michael Kors (USA), Inc., and their parents, subsidiaries and affiliate entities worldwide (individually and collectively referred to herein as “Michael Kors”, “we,” “us” or “our”) collects from and about you:

(i) on or in connection with your visits to one of our stores or otherwise offline in Germany;

(ii) through purchases you make from our catalog and have delivered to an address in Germany or through interactions with our customer service/after care service representatives; or

(iii) in connection with your visits to michaelkors.de (or any subdomain thereof), or one of our other websites, applications or other services from which you are accessing this version of Privacy Notice (each referred to herein as a “Site,” and collectively, the “Sites”). (Note: Information collected through our Careers Page is subject to a separate privacy notice, located here.)

This Privacy Notice describes what information we collect, how we use it and to whom and under what circumstances we may disclose it. The personal information we collect under this Privacy Notice is controlled by Michael Kors (Germany) GmbH, Theatiner Strasse, 36, 80333 Munich, Germany. The “personal information” we collect and process under this Privacy Notice means any information from which you can be identified and includes your name, postal address, zip or postal code, email address, telephone number, date of birth, payment information, demographic information, transaction details, IP address, site usage information and other information we may collect, depending on the circumstances.

Below is a Table of Contents for this Privacy Notice. Please select to skip directly to the different sections of this Privacy Notice to understand our practices and your rights with respect to your information:

HOW WE COLLECT INFORMATION

Information You Provide to Us

We (and our service providers) collect personal information from and when you:

  • purchase products or services from us, whether on a Site, through a catalog or in one of our stores, including after sales care services;
  • create an account with us, or otherwise sign up for a service or feature;
  • opt in to receive marketing from us (including, for example, our store associate “clienteling” communications), including through one of our third party partners acting on our behalf;
  • complete a survey;
  • participate in a sweepstake, contest or other promotion run or sponsored by Michael Kors;
  • contact our customer services team;
  • communicate with us via third-party social media sites;
  • submit a rating or review via our site; or
  • contact us, or otherwise provide information to us.

In some cases, you may provide personal information to us about another person, such as when you purchase a gift for someone and request that we ship it to that person, or when you share Site content with another person. In such cases, you confirm that you have the authorization of such person to provide us with such information.

When you are a creating an account for the first time on michaelkors.de with an email address that you have previously provided to us in another circumstance (e.g., in one of our stores, when signing up for our email communications, or by entering one of our sweepstakes or other promotions), we may recognize that email address and, once you have completed the online account set-up process, you may be able to see some of your personal information already included in your new online account. This is happening because we have recognized your email address and, for your convenience, have added your information to your online account. You can always change this information by signing into your online account.

Third-Party Sources & Publicly Available Sources

We also work closely with third parties (such as business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, address update providers, data append providers, co-promotion partners and credit reference agencies), and may lawfully receive demographic and other personal information about you from those third parties, which we may combine with the information you have provided to us. For example, we may lawfully collect information about you from content on social media platforms (e.g., when you choose to log in to our Site through a third-party social media platform (e.g., Facebook), subject to your actions and settings on those platforms). We do this to better tailor our products, services, Sites and communications, and to ensure we are providing our customers and visitors with the best shopping and browsing experiences. We process all data we obtain from such other sources in accordance with this Privacy Notice.

Note that content and information that you submit on or through Facebook, Twitter, Instagram, Tumblr and other third-party platforms may appear on our Sites through feeds or interfaces that we have with those platforms. We are not responsible for the information, content and/or privacy practices of any such third-party platforms or content pulled through them.

Site Usage Information & Other Information Collected Automatically

As part of the standard operation of the Sites, certain information is collected automatically about your visits to the Sites or your device accessing a Site. Our servers may automatically gather some of this “Site usage information” (such as your IP address, and information about your browsers, your device, your location, and your shopping, browsing and other usage activities). Additionally, if we have your consent, then we (and our service providers) may use cookies and other similar technologies to collect and track such information (see our Cookies/Ad Choices Policy for more details).

HOW WE USE PERSONAL INFORMATION

We use the personal information we collect from and about you for a variety of purposes and based on one or more legal justifications, as set out below:

PURPOSE WHAT WE USE JUSTIFICATION

To improve your experience in our stores and on the Sites including to track your activities on the Sites; to track clicks, purchases and conversion; to recognize your computer or device so that you are able to save your preferences and stay logged in to the Site without having to re-enter your online account credentials; to preserve the contents of your shopping cart and remind you if you have left items in it, or to remind you if you left the Sites without adding items to your cart; and to otherwise enhance, monitor and analyze Site usage.

Name, email address, postal address (including postcode), telephone number, date of birth, demographic information, order history, IP address, preferences, site usage information

Our legitimate business interests in providing the best shopping and browsing experiences to our customers and visitors, and to continuously improve and protect our company, property and customers against fraud (referred to as “our legitimate interest”)

To process and fulfill your requests for products and services, and to keep you informed about your requests

Name, email address, postal address (including postcode), telephone number, payment information

Performance of our contract obligations; our legitimate interest

To better understand you (including through profiling activities), in order to provide relevant, more tailored offers and messaging on and in connection with our Sites, services and products, and personalize your experience on the Sites as permitted by relevant law

Name, email address, postal address (including postcode), telephone number, date of birth, order history, IP address, preferences, site usage information

Our legitimate interest; consent

To contact you (via postal mail, email, SMS/Text, phone and/or any other method you have elected) with promotional materials about Michael Kors , its services, products, stores, events and select partners from time to time

Name, email address, postal address (including postcode), telephone number, preferences, site usage information

Consent

To contact you when necessary or appropriate in connection with your relationship with us (such as via email in regards to your rating or review submissions)

Name, email address, postal address (including postcode), telephone number, preferences, site usage information

Performance of our contract obligations; our legitimate interest

For market research and to review and improve our advertising and emails, merchandise selections, content, services, customer service, business planning, online and offline operations and overall shopping experience

Name, email address, postal address (including postcode), telephone number, date of birth, order history, IP address, site usage information

Performance of our contract obligations; our legitimate interest

To enforce our terms and conditions, and to protect the security or integrity of the Sites, our customers and our business in general (such as protecting against illegal or fraudulent activity, or misuse including cyber attacks)

Name, email address, postal address (including postcode), telephone number, date of birth, payment information, order history, IP address, site usage information

Our legitimate interest

To set up and manage your online account (including, for example, to send password reminders or notifications to changes to your account details) and to process your communication and privacy preferences

Name, email address, postal address (including postcode), telephone number, date of birth, payment information, order history, preferences, site usage information

Performance of our contract obligations; our legitimate interest

To process product returns, replacements, repairs and alterations; to resolve product issues (e.g., sending replacement products); and other customer service related issues

Name, email address, postal address (including postcode), telephone number, payment information, order history

Performance of our contract obligations; our legitimate interest

To comply with legal requirements to which Michael Kors may be subject (e.g., tax or financial reporting requirements and court orders)

Name, email address, postal address (including postcode), telephone number, date of birth, payment information

Legal obligation

If you subscribe to our newsletter, we will regularly send you our e-mail newsletter based on your consent according to Art. 6 (1) 1 lit. a) GDPR, using the data required or disclosed by you separately for this purpose. You may unsubscribe from the newsletter service at any time. For this purpose, you can either send a message to the contact option specified below or use the opt-out link in the newsletter.

We use CCTV in our stores. Please ask in store if you would like more details about how we use CCTV recordings.

Special Note Regarding Open Invoice and Direct Debit: Should you choose Open Invoice or Direct Debit as your payment method when placing an order, your information may also be used for the purposes of a credit check.

Credit Check:

On the basis of our legitimate interests and for credit checking purposes we may send personal data, specifically your name and your address, bank details, date of birth, Email as well as information about the amount of the receivable, the due date of the receivable and payment via the company Arvato Payment Solutions GmbH, Gütersloher Str. 123, 33415 Verl, Germany to the company Infoscore Consumer Data GmbH, Rheinstr. 99, 76532 Baden-Baden, Germany. Furthermore, we may obtain information concerning your previous payment history and credit-related information on the basis of mathematical and statistical methods using address data from the company Infoscore Consumer Data GmbH, Rheinstraße 99, 76532 Baden-Baden, Germany via the company Arvato Payment Solutions GmbH, Gütersloher Str. 123, 33415 Verl, Germany.

As part of the application procedure, we check your bank account details (only the IBAN and BIC or account number and bank identification number, no personal details) against the Return Debit Prevention Pool (RPP) at infoscore Consumer Data (ICD) GmbH, Rheinstr. 99, 76532, Baden-Baden, Germany. The RPP functions as a blacklist.

Klarna

In order to be able to offer you Klarna’s payment options, we will pass to Klarna certain of your personal information, such as name, billing and shipping address, email address, phone number, date of birth, bank account or card details, personal ID number and order details, in order for Klarna to assess whether you qualify for their payment options and to tailor the payment options for you. General information on Klarna you can find here. Your personal data is handled in accordance with applicable data protection law and in accordance with the information in Klarna's privacy statement.

WITH WHOM DO WE SHARE PERSONAL INFORMATION

We may disclose personal information we process for the following purposes and in the following ways, to the extent permitted by law and depending on such purpose(s) or way(s):

RECIPIENT/PURPOSE WHAT WE SHARE JUSTIFICATION

To Michael Kors (USA), Inc., 11 West 42nd St., New York, New York, 10036, USA, Michael Kors (UK) Limited and Michael Kors (Switzerland) GmbH, for all the same purposes described in the How We Use Information section above.

Name, email address, postal address (including postcode), telephone number, date of birth, demographic information, order history, IP address, payment information, preferences, site usage information

Performance of our contract obligations, our legitimate interest and/or consent depending on the purpose as described in the How We Use Information section above

To our service providers and suppliers who act as data processors for us and process such information on our behalf, for all the same purposes described in the How We Use Information section above.*

Name, email address, postal address (including postcode), telephone number, date of birth, demographic information, order history, IP address, payment information, preferences, site usage information

Performance of our contract obligations, our legitimate interest and/or consent depending on the purpose as described in the How We Use Information section above

To provide information to and as required by local law enforcement agencies, other local government authorities, or otherwise required by law or to protect the rights and safety of our property, company and customers.

Name, email address, postal address (including postcode), telephone number, date of birth, demographic information, order history, IP address, payment information

Our legitimate interest, legal obligation

On a case by case basis, in the event that Michael Kors or substantially all of its assets are acquired by one or more third parties as a result of an acquisition, merger, sale, consolidation, bankruptcy, liquidation or other similar corporate reorganization, where your information may be one of the transferred assets.

Name, email address, postal address (including postcode), telephone number, date of birth, demographic information, order history, IP address, payment information, preferences, site usage information

Our legitimate interest, legal obligation

If you have consented to our sharing of your personal information with third parties to use for their own marketing purposes, as permitted by law.

Name, email address, postal address (including postcode), telephone number, date of birth, demographic information, order history, IP address, payment information, preferences, site usage information

Consent

*These third-party partners act on our behalf and help us to operate the Sites and provide functionality, content, communications and other services, including the provision of the following services to and for us: website hosting; database hosting; address list hosting and management; email and other communications deployment and management; analytics; content and product distribution; payment processing; fulfillment; inventory management; security; and fraud detection and prevention. Current service providers include ActionIQ, Aptos, Spark::red, Metapack, Epsilon/Abacus, Sixpay, CyberSource, Oracle, Klarna, Arvato, Tulip and Twilio. If you would like to know more information about the third-party companies currently charged with such data processing, please contact us with your request at EUprivacy@michaelkors.com.

We may also use third party web analytics services, currently Google Analytics services, to help us track and analyze the use of our Site and to measure the effectiveness of our advertising, Site content and communications. These service providers are acting on our behalf and use tools such as cookies, tags and web beacons, to help us gain this understanding. (See our Cookies/Ad Choices Policy for more details on cookies, web beacons and other tags.)

If you choose to contribute to a social, community or other publicly available area or feature of our Site, the information you submit may be made available to the general public depending on your settings (which is why we recommend that you do not submit or post any personal information to such forums, such as your full name, home address, phone number and/or other information that would enable others to contact or locate you).

SMS/TEXT MESSAGES

By providing your mobile phone number and signing up to receive text/SMS messages from us (including marketing messages, such as our store associate “clienteling” messages), you consent to receive automated and other marketing and informational SMS/text messages from us (“Text Messages”). Your consent to receive Text Messages is not a prerequisite to purchasing any goods or services from us. You may not consent to receive Text Messages on behalf of someone else or provide someone else’s mobile phone number.

Message and data rates may apply to such Text Messages. Message frequency varies per month.

Text Messages are distributed via third party mobile network providers and, therefore, we cannot control certain factors relating to message delivery or guarantee availability or performance of this service, including liability for transmission delays or message failures. To receive HELP with Text Messages, contact us Europe.customerservice@michaelkors.com.

To opt out of our Text Messages, reply “STOP” to one of the Text Messages you receive. You may also choose not to receive Text Messages by emailing us at EUprivacy@michaelkors.com and specifying that this is your preference.

We may also obtain the date, time and content of your messages in the course of your use of Text Messages, and we will use such information in accordance with this Privacy Policy.

YOUR CHOICES/YOUR PRIVACY RIGHTS

You have various rights in connection with our processing of your personal information, each of which is explained below. If you wish to exercise one or more of the above rights, please contact us with your request at EUDataSubjectRequests@michaelkors.com, and include your name, email and postal address, as well as your specific request and any other information we may need in order to provide or otherwise process your request.

  • Access. You have the right to request a copy of the personal information we are processing about you, which we will provide back to you in electronic form. For your own privacy and security, in our discretion we may require you to prove your identity before providing the requested information.
  • Rectification. You have the right to have incomplete or inaccurate personal information that we process about you rectified. Note that you can always make certain adjustments to certain personal information directly through your online account.
  • Deletion. You have the right to request that we delete personal information that we process about you, except we are not obligated to do so if we need to retain such data in order to comply with a legal obligation or to establish, exercise or defend legal claims.
  • Restriction. You have the right to restrict our processing of your personal information where you believe such data to be inaccurate, our processing is unlawful or that we no longer need to process such data for a particular purpose, but where we are not able to delete the data due to a legal or other obligation or because you do not wish for us to delete it. In such case, we would mark stored personal information with the aim of limiting particular processing for particular purposes in accordance with your request, or otherwise restrict its processing.
  • Portability. You have the right to obtain personal information we hold about you, in a structured, electronic format, and to transmit such data to another data controller, where this is (a) personal information which you have provided to us, and (b) if we are processing that data on the basis of your consent (such as for direct marketing communications) or to perform a contract with you (such as to manage your online account).
  • Objection. Where the legal justification for our processing of your personal information is our legitimate interest, you have the right to object to such processing on grounds relating to your particular situation. We will abide by your request unless we have compelling legitimate grounds for the processing which override your interests and rights, or if we need to continue to process the data for the establishment, exercise or defence of a legal claim.
  • Withdrawing Consent. If you have consented to our processing of your personal information, you have the right to withdraw your consent at any time, free of charge. If you would like to withdraw consent, including if you would like to opt out of receiving marketing correspondence from us, or if you wish us to stop sharing your personal information with third party marketers, please contact us at europe.customerservice@michaelkors.com or for marketing follow the unsubscribe instructions located in the email (as relevant). (Note that we never share your payment information with other marketers.)
    • To opt out of our Text Messages, reply “STOP” to one of the Text Messages you receive. You may also choose not to receive Text Messages by emailing us at EUprivacy@michaelkors.com and specifying that this is your preference. See below for more information about our Text Messages.
    • Please understand that if you opt out of receiving promotional correspondence from us, we may still contact you in connection with your online account, relationship, activities, transactions and communications with us. Additionally, if you do request that we stop sharing your personal information with third parties for their direct marketing purposes, it is also prudent for you to opt out from or contact that third party directly.
  • Make a Complaint. You have the right to lodge a complaint with the local data protection authority if you believe that we have not complied with applicable data protection laws.

    If you are based in, or the issue relates to, Germany, the Bavarian Authority can be contacted as follows:

                Data Protection Authority of Bavaria for the Private Sector
                Telephone: +49 (0) 981 53 1300
                Email: poststelle@lda.bayern.de
                Website: https://www.lda.bayern.de/en/index.html
                Web-form: https://www.lda.bayern.de/en/complaint.html
                Address: Bayerisches Landesamt für Datenschutzaufsicht, Promenade 27 91522 Ansbach, Germany

    If you are based or the issue you would like to complain about took place elsewhere in the European Economic Area (EEA), please click here for a list of local data protection authorities in the countries within the EEA in which we operate.

Note that the rights outlined above do not extend to non-personal information.

HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION

Your personal information is stored by us and/or our service providers for as long as necessary to fulfill the specific purposes described herein and to the extent permitted by applicable laws. When we no longer have a legitimate business purpose for your personal information, or when you request that we delete your personal information (except where we need to retain it in order to comply with a legal obligation or to establish, exercise or defend legal claims), we will remove such information from our systems and records, which includes taking steps to anonymise it so that you can no longer be identified from it.

TRANSFER AND PROCESSING OF INFORMATION IN THE U.S. AND OTHER COUNTRIES

Your personal and other information may be transferred, stored, and processed in the United States, United Kingdom, Switzerland or other countries, by our affiliates and service providers, in accordance with the laws of those jurisdictions. We will ensure that this data is processed and transferred in accordance with this Privacy Statement and applicable law.

These countries may offer lower privacy protection than countries in the EEA, and your information may be subject to U.S. and foreign laws and be accessible to government, courts, police and regulatory agencies in the US and other countries. When your data is transferred outside the EEA, we ensure there are appropriate safeguards in place. For example, when your data is transferred to our affiliates in Switzerland, the European Commission has ruled that Switzerland provides adequate data protection. When transferring your data to countries which do not provide adequate data protection, Michael Kors puts additional measures in place to protect information, such as through contracts with importing entities that include model clauses approved by the European Commission (the current version of which is available here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en).

SECURITY

We have implemented technical and organizational security measures in an effort to safeguard the personal information in our custody and control. Such measures we have implemented include, for example, limiting access to personal information only to employees and authorized service providers who need to know such information for the purposes described in this Privacy Notice, as well as other administrative, technical and physical safeguards. Additionally, our service providers are not authorized to use or disclose your personal information for any purpose other than providing the services to us or on our behalf, or as otherwise may be required by applicable law. While we endeavor to always protect our systems, Sites, operations and information against unauthorized access, use, modification and disclosure, due to the inherent nature of the Internet as an open global communications vehicle and other risk factors, we cannot guarantee that any information, during transmission or while stored on our (or our service providers’) systems, will be absolutely safe from intrusion by others, such as hackers.

To provide you with increased security, certain personal information stored in your online account is only accessible via your username and password. You are responsible for maintaining the confidentiality of your online account credentials, and we strongly recommend that you do not disclose your online account username or password to anyone. We will never ask you for your password in any unsolicited communication. Please notify us immediately (see Contact Us section below) of any unauthorized use of your online account credentials or any other suspected breach of security.

CHILDREN'S PRIVACY

The Sites are not directed to children under the age of sixteen (16), and we do not knowingly collect any personal information from children under sixteen on any Site. If you are under sixteen, do not provide your personal information on, through or to any Site. Individuals who are below the age of eighteen (18) (or the age of majority in the applicable jurisdiction) should not use the Sites or our Services without authorization from a parent or legal guardian.

THIRD-PARTY WEBSITES

The Sites may contain links (which may take the form of hyperlinks, widgets, clickable logos, plug-ins, images or banners) to websites and services operated by entities other than Michael Kors. This Privacy Notice does not apply to such other websites or services, and we recommend that you review their posted privacy policies so that you understand the relevant information collection, use and disclosure practices of such other websites and services.

PHISHING, SPOOFING & OTHER SCHEMES

It has become increasingly common for hackers, cyber-criminals and other unauthorized individuals to send emails and other communications to consumers purporting to represent a legitimate company, such as a bank or an online retailer, and requesting through those communications that the consumer provide personal, often sensitive, information. Sometimes, the domain name of the sender’s email address, or the domain name of the website requesting such information, may appear to be the domain name of a legitimate, trusted company. If you receive a request to provide information (including your online account password, or any payment information) via email or to a website or individual that does not seem to be affiliated with the Sites or Michael Kors, or that otherwise seems suspicious to you, please do not respond or disclose your information. Michael Kors will never send you an email requesting that you verify any credit card information, financial information or other personal information. Please immediately report any such communication or request to us at europe.customerservice@michaelkors.com.

Additionally, Michael Kors works with customs authorities, law enforcement and legal representatives globally in an effort to prevent the sale of counterfeit Michael Kors products, both online and offline. To avoid the risk of purchasing counterfeit products, it is best to only buy directly from official Michael Kors e-commerce websites, official Michael Kors retail stores, and authorized department stores, specialty retailers and e-tailers that you know to be reputable. To report suspected counterfeit Michael Kors merchandise, please email brandprotection@michaelkors.com.

CHANGES TO THIS PRIVACY NOTICE

We may change this Privacy Notice from time to time and the amended notice will be posted to the Sites. Under certain circumstances (for example, in connection with certain material adverse changes to this Privacy Notice), we may also elect to notify you through additional means, such as posting a notice on the home page(s) of the Sites or contacting you via email.

CONTACT US

If you have any questions about this Privacy Notice and/or about the privacy policies and practices of our service providers, please contact us using the information provided on our Imprint, at EUprivacy@michaelkors.com, or at: Michael Kors, 90 Whitfield Street, London, Greater London, W1T 4EZ, Attn: Legal department.